Penetration Testing mailing list archives

Re: [PEN-TEST] HTTP Secure Session State Management


From: "van der Kooij, Hugo" <Hugo.van.der.Kooij () CAIW NL>
Date: Thu, 28 Dec 2000 21:01:23 +0100

On Thu, 28 Dec 2000, Drew Simonis wrote:

"Edwards, David (JTD)" wrote:

To attempt to bring this back "on-topic" a bit :-)

Has anyone looked at network penetration using WEBDAV/NDSDAV?
Or even seen a security evaluation of WEBDAV/NDSDAV?

Also more on topic... Don't PHP4 and MS ASP have some built in
session management features?  Has anyone hacked these methods
enough to understand what they do?

Can't tell a bit about ASP but PHP(4) does not have anything regarding
session management.

Hugo.

--
Hugo van der Kooij; Oranje Nassaustraat 16; 3155 VJ  Maasland
hvdkooij () caiw nl     http://home.kabelfoon.nl/~hvdkooij/
--------------------------------------------------------------
This message has not been checked and may contain harmfull content.


Current thread: